Cybersecurity compliance in Switzerland

Cybersecurity compliance in Switzerland is becoming increasingly complex as organisations face growing regulatory and industry-specific requirements across Switzerland and the EU. Forvis Mazars in Switzerland supports organisations with compliance assessments and the implementation of regulatory requirements to strengthen cyber resilience, improve regulatory readiness and reduce compliance risks. Our services cover Swiss supervisory and industry requirements, including FINMA, SWIFT CSP and SIC EPS, as well as key EU regulatory frameworks, including NIS 2, DORA, the Cyber Resilience Act (CRA), the AI Act and GDPR.

Cybersecurity compliance and regulatory services

Swiss cybersecurity compliance assessments and regulatory implementation
 

We support organisations in carrying out comprehensive compliance assessments against key requirements applicable in Switzerland. These include, among others, FINMA requirements, the SWIFT Customer Security Programme (CSP) and the endpoint security requirements applicable to the SIC system. Our services include regulatory assessments, gap analyses and maturity assessments with practical recommendations, as well as operational support in implementing processes and controls.

EU cybersecurity compliance and regulatory readiness assessments

We carry out structured assessments of compliance with relevant EU regulations, including NIS 2, the Digital Operational Resilience Act (DORA), the Cyber Resilience Act (CRA) and the AI Act. Based on an analysis of your existing governance, risk and control structures, we develop specific implementation recommendations and support you in meeting the regulatory requirements. Furthermore, we provide control attestation services for ICT providers in Switzerland, including Cyber Resilience Act (CRA) readiness services, in order to prove compliance to their B2B customers. The aim is to ensure your organisation is sustainably ‘regulatory-ready’ and to minimise compliance risks.

When do organisations seek cybersecurity compliance and regulatory support?

• Preparing for a FINMA review
• Mandatory SWIFT CSP or SIC EPS assessment
• Assessing compliance with Swiss cybersecurity and information security regulations
• Preparing for new EU regulatory requirements such as DORA, NIS2, CRA or the AI Act
• Conducting a regulatory gap analysis to identify weaknesses in governance, controls and processes
• Strengthening cyber resilience and operational resilience frameworks to meet regulatory expectations
• Reviewing third-party risk management and supplier oversight as part of compliance obligations
• Responding to changes in regulatory requirements or evolving supervisory expectations
• Improving documentation, evidence collection and control ownership ahead of regulatory assessments

We support organisations ranging from SMEs to large international groups operating in regulated environments in Switzerland and abroad. Our clients operate across banking, insurance, asset management, healthcare, manufacturing, technology, the public sector and many other industries, particularly those managing critical systems, sensitive data or complex regulatory requirements.

FAQs about cybersecurity compliance and regulatory support

What are the biggest challenges organisations face with DORA, CRA, NIS2 and AI Act compliance?

One of the biggest challenges in cybersecurity compliance is translating regulatory requirements into a clear operating model with defined ownership, effective controls and reliable evidence. Many organisations also face overlapping obligations across DORA, the Cyber Resilience Act (CRA), NIS2 and the AI Act, alongside growing pressure to manage third-party risk, incident reporting and documentation across business, technology, legal and procurement teams.

How can organisations assess whether their cybersecurity posture meets regulatory requirements?

The first step is to define the scope and identify the regulatory requirements that apply to your organisation. A structured cybersecurity compliance assessment should benchmark your controls against relevant frameworks and test governance, incident response, cyber resilience, supplier oversight, recovery capabilities and the evidence supporting those controls. This helps organisations understand gaps and prioritise remediation.

How should organisations prepare for DORA and other resilience-focused cyber regulations?

The most effective approach is to establish an integrated resilience programme covering governance, risk management, testing, incident management, supplier controls and evidence management. Preparing for DORA and comparable resilience-focused regulatory requirements requires clear ownership, effective controls, regular testing and up-to-date documentation that supports regulatory review and strengthens long-term cyber resilience.

How do FINMA requirements differ from DORA, NIS 2, the Cyber Resilience Act and the AI Act?

FINMA requirements apply to the relevant Swiss financial institutions, while the EU frameworks apply to different organisations, services, products and activities depending on their respective scope. Swiss organisations may therefore need to address both Swiss and EU requirements depending on their legal structure, clients, technologies, products and market presence.

What does a SWIFT CSP assessment or SIC/SNB attestation involve?

A SWIFT CSP assessment reviews compliance with the applicable mandatory security controls that underpin the annual SWIFT attestation. For the SIC system, the Swiss National Bank defines specific endpoint security requirements, including requirements relating to periodic independent assessment and attestation. The precise assessment and attestation requirements depend on the participant and applicable SIC requirements.

What is a control attestation report and who may need one?

A control attestation report provides independent assurance over defined organisational, operational or technology controls. It may be required by a specific framework or contract, or used by ICT providers to demonstrate their control environment to regulated customers.

Speak to our cybersecurity specialists

 

Want to know more?